| | |
| | | import java.util.ArrayList; |
| | | import java.util.List; |
| | | |
| | | import org.opends.messages.Message; |
| | | import org.forgerock.i18n.LocalizableMessage; |
| | | import org.opends.server.admin.server.ConfigurationChangeListener; |
| | | import org.opends.server.admin.std.server.ExternalSASLMechanismHandlerCfg; |
| | | import org.opends.server.admin.std.server.SASLMechanismHandlerCfg; |
| | |
| | | ClientConnection clientConnection = bindOperation.getClientConnection(); |
| | | if (clientConnection == null) { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | Message message = ERR_SASLEXTERNAL_NO_CLIENT_CONNECTION.get(); |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_NO_CLIENT_CONNECTION.get(); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | | } |
| | | |
| | | if(!(clientConnection instanceof LDAPClientConnection)) { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | Message message = ERR_SASLEXTERNAL_NOT_LDAP_CLIENT_INSTANCE.get(); |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_NOT_LDAP_CLIENT_INSTANCE.get(); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | | } |
| | |
| | | Certificate[] clientCertChain = lc.getClientCertificateChain(); |
| | | if ((clientCertChain == null) || (clientCertChain.length == 0)) { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | Message message = ERR_SASLEXTERNAL_NO_CLIENT_CERT.get(); |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_NO_CLIENT_CERT.get(); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | | } |
| | |
| | | { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | Message message = ERR_SASLEXTERNAL_NO_MAPPING.get(); |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_NO_MAPPING.get(); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | | } |
| | |
| | | { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | Message message = ERR_SASLEXTERNAL_NO_CERT_IN_ENTRY.get( |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_NO_CERT_IN_ENTRY.get( |
| | | String.valueOf(userEntry.getName())); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | |
| | | { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | Message message = ERR_SASLEXTERNAL_PEER_CERT_NOT_FOUND.get( |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_PEER_CERT_NOT_FOUND.get( |
| | | String.valueOf(userEntry.getName())); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | |
| | | |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | Message message = ERR_SASLEXTERNAL_CANNOT_VALIDATE_CERT.get( |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_CANNOT_VALIDATE_CERT.get( |
| | | String.valueOf(userEntry.getName()), |
| | | getExceptionMessage(e)); |
| | | bindOperation.setAuthFailureReason(message); |
| | |
| | | { |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | Message message = ERR_SASLEXTERNAL_PEER_CERT_NOT_FOUND.get( |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_PEER_CERT_NOT_FOUND.get( |
| | | String.valueOf(userEntry.getName())); |
| | | bindOperation.setAuthFailureReason(message); |
| | | return; |
| | |
| | | |
| | | bindOperation.setResultCode(ResultCode.INVALID_CREDENTIALS); |
| | | |
| | | Message message = ERR_SASLEXTERNAL_CANNOT_VALIDATE_CERT.get( |
| | | LocalizableMessage message = ERR_SASLEXTERNAL_CANNOT_VALIDATE_CERT.get( |
| | | String.valueOf(userEntry.getName()), |
| | | getExceptionMessage(e)); |
| | | bindOperation.setAuthFailureReason(message); |
| | |
| | | @Override() |
| | | public boolean isConfigurationAcceptable( |
| | | SASLMechanismHandlerCfg configuration, |
| | | List<Message> unacceptableReasons) |
| | | List<LocalizableMessage> unacceptableReasons) |
| | | { |
| | | ExternalSASLMechanismHandlerCfg config = |
| | | (ExternalSASLMechanismHandlerCfg) configuration; |
| | |
| | | */ |
| | | public boolean isConfigurationChangeAcceptable( |
| | | ExternalSASLMechanismHandlerCfg configuration, |
| | | List<Message> unacceptableReasons) |
| | | List<LocalizableMessage> unacceptableReasons) |
| | | { |
| | | return true; |
| | | } |
| | |
| | | { |
| | | ResultCode resultCode = ResultCode.SUCCESS; |
| | | boolean adminActionRequired = false; |
| | | ArrayList<Message> messages = new ArrayList<Message>(); |
| | | ArrayList<LocalizableMessage> messages = new ArrayList<LocalizableMessage>(); |
| | | |
| | | |
| | | // See if we should attempt to validate client certificates against those in |